Great Circle Associates Firewalls
(October 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: sex, lies, and firewall code
From: Bernd Eckenfels <lists @ lina . inka . de>
Date: Tue, 21 Oct 1997 04:51:55 +0200
To: Peter da Silva <peter @ baileynm . com>
Cc: Joe Judge <joej @ ultranet . com>, joej @ joesmac . ultranet . com, craig . wright @ asx . com . au, rick @ paimail . com, firewalls @ GreatCircle . COM
In-reply-to: <9710202308 . AA22149 @ baileynm . com>; from Peter da Silva on Mon, Oct 20, 1997 at 06:08:09PM -0500
References: <344BDDB3 . 484880DD @ ultranet . com> <9710202308 . AA22149 @ baileynm . com>

Hello,

On Oct 20, Peter da Silva wrote
> > I want to pass DCE's portmap-equiv (called epmapper) so I plug
> > the xxx port. I've restricted DCE to a range of ports (3000-4000)
> > and I need to place 1000 plug-gw's  ???  
> 
> A shortcoming in the Berkeley socket interface. It's hard to wait on
> more than one port from a given process. If anyone has ideas for how
> to handle that cleanly I'd be interested in adding that to plugdaemon.

Well, you can select() on at least 128 Ports. With Linux Port Redirection
feature one can do something like:

ipfwadm -I -i acc -P tcp -S0/0 -D 1.2.3.4 1000:2000 -r 3000

This will redirect all connections to port 1000 .. 2000 to Port 3000 (on
address 1.2.3.4). A Programm running on Port 3000 can get the destination
port by using getsockname(). I think this is brokwn in 2.0.30. 

The great advantage of this is, that you only have to wait on one socket.

Greetings
Bernd
-- 
  (OO)      -- Bernd_Eckenfels @
 Wittumstrasse13 .
 76646Bruchsal .
 de --
 ( .. )  ecki @
 {inka .
 de,linux.de,debian.org} http://home.pages.de/~eckes/
  o--o     *plush*  2048/93600EFD  eckes @
 irc  +4972573817  BE5-RIPE
(O____O)       If privacy is outlawed only Outlaws have privacy


References:
Indexed By Date Previous: Re: sex, lies, and firewall code
From: Rick Murphy <rick @ paimail . com>
Next: Re: sex, lies, and firewall code
From: Anton J Aylward <anton @ Toronto . com>
Indexed By Thread Previous: Re: sex, lies, and firewall code
From: Brian Mitchell <brian @ firehouse . net>
Next: RE: sex, lies, and firewall code
From: Ryan Russell/SYBASE <Ryan . Russell @ sybase . com>

Google
 
Search Internet Search www.greatcircle.com